
PEACH
Uma estrutura de isolamento de inquilino
CVE-2026-100693 is a Server-Side Request Forgery (SSRF) / security restriction bypass vulnerability in the Hugo static site generator, caused by improper handling of case sensitivity in the security.http.urls IP-literal deny rule. Attackers can supply mixed-case URL schemes (e.g., HTTP://127.0.0.1/) in resources.GetRemote calls to bypass the deny rule and fetch content from restricted IP addresses such as localhost. The vulnerability affects Hugo versions v0.162.0 through v0.165.x (before v0.166.0) and was publicly disclosed on September 26, 2026. It carries a CVSS v3.1 base score of 8.4 (High) and a CVSS v4.0 base score of 8.6 (High) (GitHub Advisory, Hugo Security Advisory).
The root cause is classified as CWE-178 (Improper Handling of Case Sensitivity) and CWE-918 (Server-Side Request Forgery). Hugo's security.http.urls allowlist is the sole control governing outbound HTTP fetches made by the resources.GetRemote function; the default IP-literal deny rule performed a case-sensitive comparison, meaning that an uppercase or mixed-case scheme such as HTTP://127.0.0.1/ or Http://localhost/ bypassed the restriction while other default rules were already case-insensitive (Hugo Security Advisory). The attack vector is local (an attacker must be able to influence Hugo template content or configuration), requires no privileges, and has low attack complexity (GitHub Advisory). The vulnerability was discovered by researcher Reload3d and reported to the Hugo project (Hugo Security Advisory).
Successful exploitation allows an unauthenticated local user (or any party able to supply untrusted URLs to resources.GetRemote) to access restricted network resources such as localhost services, internal APIs, or metadata endpoints that the IP-literal deny rule was intended to block. The CVSS scoring reflects high confidentiality, integrity, and availability impact on the vulnerable system, meaning an attacker could read sensitive local data, potentially manipulate content fetched during site builds, or disrupt the build process (GitHub Advisory, Red Hat Bugzilla). The scope is limited to the vulnerable Hugo build environment and does not propagate to subsequent systems.
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.13% (3rd percentile), indicating a low near-term exploitation probability. Exploitation requires local access or the ability to influence Hugo template/configuration content, which limits the attacker pool.
resources.GetRemote is used in templates or shortcodes with attacker-influenced URL input.HTTP://127.0.0.1:8080/internal-api or Http://localhost/admin.resources.GetRemote call: Supply the crafted URL as input to a Hugo template that passes it to resources.GetRemote, either by modifying a content file, shortcode parameter, or configuration that feeds into the template.hugo or triggering a CI/CD pipeline), which will invoke resources.GetRemote with the crafted URL.resources.GetRemote calls with mixed-case URL schemes (e.g., HTTP://, Http://, HTTPS://) targeting loopback or private IP ranges (127.0.0.0/8, 169.254.0.0/16, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).169.254.169.254 for cloud instance metadata).netstat, ss, or EDR telemetry).Upgrade Hugo to version v0.166.0 or later, which fixes the IP-literal deny rule to perform case-insensitive scheme matching (Hugo Security Advisory). As an interim workaround, avoid passing untrusted or user-controlled URLs to resources.GetRemote, or replace the default deny-list approach with an explicit allow-list of trusted hosts in security.http.urls (Hugo Security Advisory). Organizations using Hugo in CI/CD pipelines should audit template and shortcode inputs for externally influenced URL parameters.
The vulnerability was noted on Mastodon by The Hacker Wire shortly after disclosure, and was tracked by standard vulnerability aggregators including VulnDB, CVEFeed, and OSV (GitHub Advisory). Red Hat opened a Bugzilla entry and assigned medium severity, reflecting the local attack vector constraint (Red Hat Bugzilla). No significant broader media coverage or notable researcher commentary beyond the initial advisory has been observed.
Disponibilidade de correção em distribuições Linux principais e suas versões.
bionic (esm-apps)
hugo
devel
hugo
focal (esm-apps)
hugo
jammy
hugo
jammy (esm-apps)
hugo
noble
hugo
noble (esm-apps)
hugo
resolute
hugo
Origem: Este relatório foi gerado usando IA
Avaliação de vulnerabilidade gratuita
Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.
Marque uma demonstração personalizada
"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."